|
Oct 30, 2025 |
CISA
|
Alert
|
CISA Releases Two Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-303-01 International Standards Organization ISO 15118-2 ICSA-25-303-02 Hitachi Energy TropOS This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Oct 30, 2025 |
CISA
|
Alert
|
New Guidance Released on Microsoft Exchange Server Security Best Practices
Threat activity targeting Exchange continues to persist, and organizations with unprotected or misconfigured Exchange servers remain at high risk of compromise. This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA, NSA |
|
Oct 28, 2025 |
CISA
|
Alert
|
CISA Releases Three Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-301-01 Schneider Electric EcoStruxure ICSMA-25-301-01 Vertikal Systems Hospital Manager Backend Services ICSA-24-352-04 Schneider Electric Modicon (Update B) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Oct 24, 2025 |
CISA
|
Alert
|
Microsoft Releases Out-of-Band Security Update to Mitigate Windows Server Update Service Vulnerability, CVE-2025-59287
Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE-2025-59287 , that a prior update did not fully mitigate.
|
CISA |
|
Oct 24, 2025 |
CERT-EU
|
Advisory
|
2025-040: Critical Vulnerability in Windows Server Update Service (WSUS)
This vulnerability could allow a remote unauthenticated attacker to execute code on the targeted systems [1]. A proof-of-concept is publicly available for this vulnerability [2].
|
CERT-EU |
|
Oct 23, 2025 |
CISA
|
Alert
|
CISA Releases Eight Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-296-01 AutomationDirect Productivity Suite ICSA-25-296-02 ASKI Energy ALS-Mini-S8 and ALS-Mini-S4 ICSA-25-296-03 Veeder-Root TLS4B Automatic Tank Gauge System ICSA-25-296-04 Delta Electronics ASDA-Soft ICSMA-25-296-01 NIHON KOHDEN Central Monitor CNS-6201 ICSA-25-037-02 Schneider Electric EcoStruxure (Update C) ICSA-24…
|
CISA |
|
Oct 21, 2025 |
CISA
|
Alert
|
CISA Releases 10 Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-294-01 Rockwell Automation 1783-NATR ICSA-25-294-02 Rockwell Automation Compact GuardLogix 5370 ICSA-25-294-03 Siemens SIMATIC S7-1200 CPU V1/V2 Devices ICSA-25-294-04 Siemens RUGGEDCOM ROS Devices ICSA-25-294-05 CloudEdge Online Cameras and App ICSA-25-294-06 Raisecomm RAX701-GC Series ICSMA-25-294-01 Oxford Nanopore…
|
CISA |
|
Oct 16, 2025 |
CISA
|
Alert
|
CISA Releases Thirteen Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-289-01 Rockwell Automation FactoryTalk View Machine Edition and PanelView Plus 7 ICSA-25-289-02 Rockwell Automation FactoryTalk Linx ICSA-25-289-03 Rockwell Automation FactoryTalk ViewPoint ICSA-25-289-04 Rockwell Automation ArmorStart AOP ICSA-25-289-05 Siemens Solid Edge ICSA-25-289-06 Siemens SiPass Integrated ICSA-…
|
CISA |
|
Oct 15, 2025 |
CISA
|
Alert
|
CISA Directs Federal Agencies to Mitigate Vulnerabilities in F5 Devices
A nation-state affiliated cyber threat actor has compromised F5 systems and exfiltrated data, including portions of the BIG-IP proprietary source code and vulnerability information, which provides the actor with a technical advantage to exploit F5 devices and software. This poses an imminent threat to federal networks using F5 devices and software.
|
CISA |
|
Oct 15, 2025 |
CERT-EU
|
Advisory
|
2025-039: High Severity Vulnerability in FortiOS
ThevulnerabilityCVE-2025-58325,withaCVSSscoreof7.8,isanIncorrectProvisionofSpecified Functionality flow that may allow a local authenticated attacker to execute system commands via crafted CLI commands. The following product versions are affected: The following platforms are affected: 100E/101E, 100F/101F, 1100E/1101E, 1800F/1801F, 2200E/2201E, 2600F/2601F, 3300E/3301E,3400E/3401E,3500F/3501F,3600E/3601E,3800D,3960E,3980E,4200F/4201F, 4400F/4401F…
|
CERT-EU |
|
Oct 15, 2025 |
CERT-EU
|
Advisory
|
2025-038: Critical Vulnerabilities in Veeam Backup
CERT-EU recommends updating affected software as soon as possible and following Veeam implementation best practices [2]. The vulnerability CVE-2025-48983, with a CVSS score of 9.9, resides in the Mount service of Veeam Backup & Replication and allows an authenticated domain user to execute arbitrary code on backup infrastructure hosts.
|
CERT-EU |
|
Oct 15, 2025 |
CERT-EU
|
Advisory
|
2025-037: Multiple Vulnerabilities in F5 Products
Thisincludedaccessto BIG-IP product development source code and to information related to security vulnerabilities that had not yet been disclosed nor patched. F5 released patches on the same day to address There is currently no known exploitation of these vulnerabilities.
|
CERT-EU |
|
Oct 15, 2025 |
JPCERT/CC
|
Alert
|
Microsoft Releases October 2025 Security Updates
Microsoft has released October 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild.
|
JPCERT/CC |
|
Oct 14, 2025 |
CISA
|
Alert
|
CISA Releases One Industrial Control Systems Advisory
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-287-01 Rockwell Automation 1715 EtherNet/IP Comms Module This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Oct 9, 2025 |
CISA
|
Alert
|
CISA Releases Four Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-282-01 Hitachi Energy Asset Suite ICSA-25-282-02 Rockwell Automation Lifecycle Services with Cisco ICSA-25-282-03 Rockwell Automation Stratix ICSA-25-128-03 Mitsubishi Electric Multiple FA Products (Update A) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Oct 7, 2025 |
CISA
|
Alert
|
CISA Releases Two Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-280-01 Delta Electronics DIAScreen ICSA-25-226-31 Rockwell Automation 1756-EN4TR, 1756-EN4TRXT (Update B) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Oct 2, 2025 |
CISA
|
Alert
|
CISA Releases Two Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-275-01 Raise3D Pro2 Series 3D Printers ICSA-25-275-02 Hitachi Energy MSM Product This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |